Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp12017051ybi; Fri, 26 Jul 2019 03:24:34 -0700 (PDT) X-Google-Smtp-Source: APXvYqxzxDVQfl/d7Bo2F2lUkDqrfxsIX5u1MavytvyYib6SQBtVIOU5mkC6thPSGYrwx+H/mHPC X-Received: by 2002:aa7:8dd2:: with SMTP id j18mr21223110pfr.88.1564136674837; Fri, 26 Jul 2019 03:24:34 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1564136674; cv=none; d=google.com; s=arc-20160816; b=UvYtujn9B8eq12I97680EVf6kcYTuCL/jCi3iDFibgtSuFlkANOZpB50HJJy5ZyT4h EaJQt0zfTfioJkPQEArJWjXl5fKdFX6e6GXNKc25pjW7MTR4HrUem32KYYuyrwQWOMe3 GyXm2Vh44zTK7Psg3T+DQVfGQI6ajaBDJAxVqiVj+/cODSUX+52WsWt/Mqu+FSYTKo40 5Zp4xwYUY2TM1FNY51XX0YVSuSsMZS2rFsAgBplvdhNgQXgqiYvYVK58ynHVd8XzCh8K MZrsXEygGTNHQ+okPQCIRg25hvNb8JjpUX1FH2Yb5l8ZVy83AuZeK5DO55h/XbZUp7ba U92A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:date:subject:cc:to:from :dkim-signature; bh=vy+KcGLywvSXtldrxHurSPKwSpgydiwK45sZFxwJSSA=; b=mBQq1D93jcBWSYCJYGvl3tG6zj695VzCI5yPvdCa2FH4Y9w2atlhTrJqDjZ2tzvcgW 6XwoUYnvypLr2A3wy1/GXgeTbZ8rKHTa+uLjsfBvOofbOpL037yF76O6QjfZW+tAVDhg VaBumVGNN62jHSsC58z7InOKjMZBYSkULz7TD1k4ktigJ9eajlJQ+audvOxMF2EE/x40 QO4YXqUgtVKG5aRuRRPogexkmtmVNB4v+eevQ6ssU8PzQL8gI4QpSYMXYEi4v9SHWE36 6ym++PEKp5taJvSJ3A0IRY0uOrkaaKhKwegrjbvqpGS5p7rbnbvHa3rWt1gS2HZ5ZBCa IYug== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ZZX+j1+G; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id k11si19063253pfi.3.2019.07.26.03.24.19; Fri, 26 Jul 2019 03:24:34 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ZZX+j1+G; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726271AbfGZKXf (ORCPT + 99 others); Fri, 26 Jul 2019 06:23:35 -0400 Received: from mail-pg1-f194.google.com ([209.85.215.194]:34537 "EHLO mail-pg1-f194.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725944AbfGZKXf (ORCPT ); Fri, 26 Jul 2019 06:23:35 -0400 Received: by mail-pg1-f194.google.com with SMTP id n9so18351977pgc.1; Fri, 26 Jul 2019 03:23:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=vy+KcGLywvSXtldrxHurSPKwSpgydiwK45sZFxwJSSA=; b=ZZX+j1+GLqOiZCZe44SRIgvt/sKqpR0yspUiWW/FfVzn/IScs7Q/OD4i37oVFgfT58 MNFz+qO+euHt7eiazkJKceM1RHhraNHjcF4hUeglCHsnTJH+NJdgY3NZAKkphXAlLWkh 0x6br3QR1WbjlBpvFivakfxlWG/bmSp38vGenbUtVS3UZUvk2giNxuID7YdVAV95MbJH KKHFX590XxVZt7uD/GcYVqARGFrSEnVkr6unubIjiiNPJ6n0bGmRXt33R8DOklxhg0Sz i/oYrlWJc/pkJErYDe94eGIQ0lMlO19uIFdr/2OjYeqOncjTRvSIE7Sa7u0+zl3ntIDw ouLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=vy+KcGLywvSXtldrxHurSPKwSpgydiwK45sZFxwJSSA=; b=eRATD3WMjtyW6UTKRnd7CSitIVAqS2IoTJkGfj8XS8nFEfSxbuuF9Efhre1JTE5ZnO xl0Zd7AdBkn0YZ92VY1pLz15uHv91rhIh/xfORnRNbILsdAbZnK9CcuYR9bwf19PdPl9 wKSN/xQMPA3cN17lZxpUp6yqrDvVvqFkli7zOXMGyTxKcJbzyOQ9jnn3LmVmWhJ/fbcr i1P84lo/Q48/7+xx/yZSNsHtN9EukT/ZgPvt54F9vdq9Gy7Cb41Z2lijr6bWMJ2w3q5o WvE1+V1KgXuqopHynYuyS0oKnexe88DICdotJv/s23U/Lq7Yj+O0v2H19jx1PId211EV Lqjg== X-Gm-Message-State: APjAAAVqpdTBVLwgb+L7ltASi2YxiiO7flvPK+lgeuKMDwXchmhb32QL efS+U9XyBaTAivitmAM99yc= X-Received: by 2002:a63:5f09:: with SMTP id t9mr57356468pgb.351.1564136614760; Fri, 26 Jul 2019 03:23:34 -0700 (PDT) Received: from oslab.tsinghua.edu.cn ([2402:f000:4:72:808::3ca]) by smtp.gmail.com with ESMTPSA id l4sm52896146pff.50.2019.07.26.03.23.32 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 26 Jul 2019 03:23:34 -0700 (PDT) From: Jia-Ju Bai To: dmitry.torokhov@gmail.com, allison@lohutok.net, gregkh@linuxfoundation.org, tglx@linutronix.de, rdunlap@infradead.org Cc: patches@opensource.cirrus.com, linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jia-Ju Bai Subject: [PATCH v3] input: touchscreen: wm97xx-core: Fix possible null-pointer dereferences in wm97xx_ts_input_open() Date: Fri, 26 Jul 2019 18:23:26 +0800 Message-Id: <20190726102326.9266-1-baijiaju1990@gmail.com> X-Mailer: git-send-email 2.17.0 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In wm97xx_ts_input_open(), there is an if statement on line 507 to check whether wm->mach_ops is NULL: if (wm->mach_ops && wm->mach_ops->acc_enabled) When wm->mach_ops is NULL, it is used on line 521: wm97xx_init_pen_irq(wm); BUG_ON(!wm->mach_ops->irq_enable); BUG_ON(!wm->mach_ops->irq_gpio); wm97xx_reg_write(..., reg & ~(wm->mach_ops->irq_gpio)) Thus, possible null-pointer dereferences may occur. To fix these bugs, wm->mach_ops is checked at the beginning of wm97xx_init_pen_irq(). These bugs found by a static analysis tool STCheck written by us. Signed-off-by: Jia-Ju Bai --- v2: * Add a new check of wm->mach_ops in wm97xx_init_pen_irq(). Thank Charles for helpful advice. v3: * Print a message if wm->mach_ops is NULL in wm97xx_init_pen_irq(). Thank Charles for helpful advice. --- drivers/input/touchscreen/wm97xx-core.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/input/touchscreen/wm97xx-core.c b/drivers/input/touchscreen/wm97xx-core.c index 0a174bd82915..bf754cb8965c 100644 --- a/drivers/input/touchscreen/wm97xx-core.c +++ b/drivers/input/touchscreen/wm97xx-core.c @@ -374,6 +374,11 @@ static int wm97xx_init_pen_irq(struct wm97xx *wm) { u16 reg; + if (!wm->mach_ops) { + dev_err(wm->dev, "mach_ops is NULL"); + return -EINVAL; + } + /* If an interrupt is supplied an IRQ enable operation must also be * provided. */ BUG_ON(!wm->mach_ops->irq_enable); -- 2.17.0